Threat Database Hacktool PUP.Gamehack.X

PUP.Gamehack.X

The detection of PUP.Gamehack.X on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.

What Is PUP.Gamehack.X?

PUP.Gamehack.X is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often come bundled with other software or are downloaded from untrusted sources, and can be difficult to remove once installed.

How PUP.Gamehack.X Operates

PUPs like PUP.Gamehack.X typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, search history, and other personal information, which can be used for targeted advertising or other malicious purposes. In some cases, PUPs may also install additional software or modify system settings to further compromise your computer's security.

Symptoms of Infection

If your system is infected with PUP.Gamehack.X, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings or homepage. You may also notice that your system is running more slowly than usual, or that certain programs or applications are not functioning properly. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and monitor your system for any suspicious activity.

How to Remove PUP.Gamehack.X

  1. Boot your system in Safe Mode with Networking to prevent any malicious programs from running and to allow you to access the internet to download removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove any malicious software.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.Gamehack.X infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that all malicious software has been removed.

Conclusion

Removing PUP.Gamehack.X from your system requires a combination of technical knowledge and caution. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your computer running smoothly and securely. Remember to always be cautious when downloading software or clicking on links from untrusted sources, and to run regular virus scans to detect and remove any malicious software that may be present on your system.

Analysis Report

General information

Family Name: PUP.Gamehack.X
Signature status: No Signature

Known Samples

MD5: 9cb1858a9bfb5c87c4600c68c717d7b4
SHA1: fc7d7f6868c0ad761065b063ce82a7a3fee3022a
SHA256: A330868F9FCF8B08CEB60DAB33F2F6FBE0289FF11E2F6C2CF624FD66DE9C280D
File Size: 2.77 MB, 2772575 bytes
MD5: 5981b4955b4ab80da1cf9f3dcb2f4a0e
SHA1: 38ac7c382a2e35747928aa73f6ece2955efb7d7b
SHA256: 4018E035A3B76A354923AD6F2ED562892A638CFB4507C5D91977DC4BF65C50BB
File Size: 2.74 MB, 2737023 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • big overlay
  • dll
  • x64

Block Information

Total Blocks: 3,027
Potentially Malicious Blocks: 327
Whitelisted Blocks: 1,603
Unknown Blocks: 1,097

Visual Map

0 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 x x 0 ? ? ? x x 0 0 0 0 ? ? x 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 1 0 0 0 ? ? ? ? 0 x x ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? ? ? 0 0 ? x 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? x ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? x ? ? 0 0 ? ? ? ? ? 0 0 ? x ? 0 ? ? ? 0 ? x ? ? ? ? ? ? x ? ? ? ? 0 x ? ? x 0 ? ? 0 ? 0 ? ? ? ? ? x ? ? ? 1 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? x x x x x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? ? ? 0 0 ? ? ? 0 x ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? ? ? ? x x 0 ? x ? 0 x ? x x x ? 0 ? ? 0 ? 0 0 ? ? ? ? 0 0 ? ? ? x ? ? x ? 0 0 x ? x ? ? ? ? 0 ? ? 0 ? ? ? ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 x ? 0 ? ? ? ? ? ? ? 1 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? x 0 ? 0 0 ? 0 0 ? 0 ? ? ? 0 0 ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? 0 x x ? 0 0 x x ? 0 0 x ? 0 ? 0 ? ? 0 ? 1 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 ? 0 x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? 1 ? 0 ? ? ? 0 ? ? ? x ? ? ? ? ? 0 ? ? ? x ? ? 0 0 ? ? 0 x ? 0 x ? 0 ? x ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 0 0 0 0 ? ? 0 x 0 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 x 0 0 0 x x x ? 0 x x ? x x x x ? x x x x ? x x x x x 0 x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x ? ? ? ? x x x x x x x x x x ? x x x x ? x x x x x x ? x ? ? ? 1 x ? x 0 0 0 0 ? x x x ? 0 x x x 0 x x x 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 1 ? ? ? ? 0 ? ? 0 ? ? ? x ? x 0 0 x ? ? ? ? ? x ? ? ? 0 0 ? ? ? ? x 0 0 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 x x ? ? ? x x ? ? ? ? x ? x ? 0 0 ? ? ? ? ? 1 0 0 ? ? ? x x 0 ? 0 0 0 ? ? ? ? x x ? 0 0 x 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 1 0 0 0 0 ? 0 ? x x ? ? ? ? 0 0 0 0 0 0 x ? ? ? ? ? 0 ? ? ? 0 0 ? x x ? x x ? 1 0 ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 1 ? ? x ? x ? x ? x x 0 ? ? ? ? 1 ? ? ? x 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? x 0 ? x x ? ? ? ? ? ? ? ? ? ? 0 ? x ? ? x x ? ? 0 ? ? ? x ? x 0 ? ? ? ? ? ? ? 0 ? ? 1 ? ? ? 0 ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? 1 ? x ? ? 0 ? x ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? x ? ? ? ? 0 0 ? ? 1 1 ? ? 1 ? ? 1 ? ? 1 ? ? ? ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? 1 ? ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 1 x ? 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 x ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...